Medium severityNVD Advisory· Published Apr 21, 2026· Updated Apr 29, 2026
CVE-2026-40939
CVE-2026-40939
Description
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is fixed in 2.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dev.dsf:dsf-common-jettyMaven | >= 0 | — |
dev.dsf:dsf-fhir-serverMaven | >= 0 | — |
dev.dsf:dsf-bpe-serverMaven | >= 0 | — |
Affected products
4- ghsa-coords3 versions
>= 0+ 2 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-gj7p-595x-qwf5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-40939ghsaADVISORY
- dsf.dev/operations/v2.1.0/bpe/oidc.htmlnvdWEB
- dsf.dev/operations/v2.1.0/fhir/oidc.htmlnvdWEB
- github.com/datasharingframework/dsf/commit/7d25feafb83d66cb59985ac88568b67d937b1937ghsaWEB
- github.com/datasharingframework/dsf/commit/f4ecb002f7d12642f92da6b79371ed367d0140e7nvdWEB
- github.com/datasharingframework/dsf/security/advisories/GHSA-gj7p-595x-qwf5nvdWEB
News mentions
0No linked articles in our index yet.